Lead Identity & Access Management Engineer

Koch

Región Centro

Presencial

MXN 900.000 - 1.300.000

Jornada completa

hace 39 horas
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca la empresa.

Supera los filtros ATS

Descripción de la vacante

Koch seeks a Lead IAM Engineer to define global identity strategy, architecture, and platforms. You will lead authentication, federation, and governance, building scalable automation and secure access across the enterprise.

This role focuses on SAML2, OAuth2/OIDC, and FIDO2, with hands-on coding, design governance, and IAM platform leadership. In-office presence in Zapopan, Mexico is required.

Formación

  • Experience owning identity platforms at scale with deep protocol expertise (SAML, OAuth2/OIDC, SCIM, FIDO2).
  • Hands-on architecture across Azure Entra ID, AWS IAM, or Google Cloud Identity.
  • Experience designing infrastructure across Azure/AWS/GCP.
  • Strong coding skills in Python and/or TypeScript with API integrations and CI/CD.

Responsabilidades

  • Define reusable IAM patterns for SSO, federation, and workload identity.
  • Lead design governance and reviews for new apps and platform changes.
  • Design and implement SAML2/OAuth2/OIDC/WS-Fed and MFA with adaptive controls.
  • Operate and enhance enterprise identity services (PingOne or equivalents).
  • Serve as lead developer driving code for identity platforms and connectors.
  • Build RBAC/ABAC/PBAC models and IGA workflows.
  • Lead end-to-end JML automation integrating HRIS, ITSM, and directories via SCIM.
  • Manage Identity as Code with Terraform and CI/CD pipelines.
  • Implement Zero Trust principles and continuous verification with monitoring and revocation.
  • Provide incident leadership for auth outages and credential compromise.

Conocimientos

Identity platforms
SAML/OAuth2/OIDC
SCIM
FIDO2/passkeys
RBAC/ABAC/PBAC
Terraform
CI/CD
Python/TypeScript

Herramientas

PingOne
PingOne DaVinci
Azure Entra ID
AWS IAM
GCP Identity
Okta
SailPoint IdentityNow/IdentityIQ

Descripción del empleo

Lead Identity & Access Management Engineer

We are looking for a Lead IAM Engineer to define and evolve Koch's global identity strategy, architecture, and platforms. This role will serve as a technical leader for authentication, federation, authorization, identity governance, and lifecycle automation across the enterprise, enabling secure access experiences for users, applications, and services worldwide. Working closely with global architects, engineers, security teams, business partners, and customers, this individual will help shape the future of Identity at Koch through modern authentication technologies, Zero Trust principles, and scalable automation.

Our Team

The Koch Technology Identity team provides modern Identity solutions and services for all Koch businesses. We are responsible for the entire enterprise in designing innovative services, creating, and sharing best practices, and providing support for our services.

This role requires an in-office presence in our Zapopan office
What You Will Do
  • Set IAM architecture & standards: Define reusable patterns for SSO/federation, authorization models, privileged access, and workload/machine identity.
  • Lead design governance: Run identity design reviews for new applications and major platform changes; approve patterns, manage exceptions, and drive adoption.
  • Build authentication & federation: Design and implement SAML2, OAuth2/OIDC, WS-Fed, and FIDO2/passkeys, including adaptive/risk-based auth, conditional access, and MFA.
  • Engineer IAM platforms: Operate and enhance enterprise identity services (PingOne / PingOne DaVinci or equivalent orchestration platforms).
  • Lead developer for IAM platforms: Serve as lead developer driving hands-on code development to build, extend, and maintain new and existing identity platforms, including custom connectors, APIs, and orchestration flows.
  • Design authorization & governance: Build scalable RBAC/ABAC/PBAC models, entitlement catalogs, role engineering, and access request workflows (IGA).
  • Automate identity lifecycle: Lead and design end-to-end JML automation integrating HRIS, ITSM, directories, and apps via SCIM and event-driven pipelines.
  • Identity as Code: Manage identity configuration/policy using Terraform and CI/CD with testing, version control, and deployment discipline.
  • Zero Trust & Detection: Implement least privilege and continuous verification; integrate ITDR-style monitoring, logging, alerting, SLOs, and rapid revocation.
  • Incident leadership: Act as escalation for auth outages, federation issues, and credential compromise; lead RCA and post-incident hardening.
  • Influence & mentoring: Partner globally with architects, developers, and security; coach engineers through reviews, playbooks, and training.
Who You Are (Basic Qualifications)
  • Extensive experience owning identity platforms at scale, with deep protocol-level expertise across SAML, OAuth2/OIDC, SCIM, FIDO2/passkeys, LDAP, and Kerberos.
  • Hands-on architecture across Azure Entra ID, AWS IAM, or Google Cloud Identity, including cross-cloud federation and hybrid identity patterns.
  • Practical experience designing and building infrastructure across Azure, AWS, or GCP.
  • Strong coding skills in Python and/or TypeScript, with API integrations, Git, CI/CD, and automated testing. Delivery of identity configuration as versioned, testable code using Terraform or similar technologies.
  • Hands-on experience integrating diverse applications with enterprise governance platforms; design and delivery of JML automation, RBAC/ABAC/PBAC models and access workflows integrating HRIS -> IAM -> downstream apps via SCIM and event-driven pipelines.
What Will Put You Ahead
  • Experience building multi-step user journeys for Workforce, CIAM, and partner ecosystems using platforms such as PingOne DaVinci or Okta Workflows.
  • Hands-on development and design experience with SailPoint IdentityNow/IdentityIQ (or equivalent).
  • Real-time detection and response to identity-based threats, integrating signals from IdPs, directories, and SIEM/SOAR platforms.

At Koch companies, we are entrepreneurs. This means we openly challenge the status quo, find new ways to create value and get rewarded for our individual contributions. Any compensation range provided for a role is an estimate determined by available market data. The actual amount may be higher or lower than the range provided considering each candidate's knowledge, skills, abilities, and geographic location.

Who We Are

Koch creates and innovates a wide spectrum of products and services that make life better. Our work spans a vast number of industries across the world, including engineered technology, refining, chemicals and polymers, pulp and paper, glass, electronics and many more. Headquartered in Wichita, Kansas, Koch employs about 120,000 employees across the globe.

At Koch, employees are empowered to do what they do best to make life better. Learn how our business philosophy helps employees unleash their potential while creating value for themselves and the company.

Additionally, everyone has individual work and personal needs. We seek to enable the best work environment that helps you and the business work together to produce superior results.

Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Lead Identity & Access Management Engineer
Lead Identity & Access Management Engineer

Flint Hills Resources • Región Centro

Presencial
MXN 900.000 - 1.400.000
Global IAM Architect: Zero Trust & Automation
Global IAM Architect: Zero Trust & Automation

Flint Hills Resources • Región Centro

Presencial
MXN 900.000 - 1.400.000
Global IAM Lead: Zero Trust & Automation Architect
Global IAM Lead: Zero Trust & Automation Architect

Koch • Región Centro

Presencial
MXN 900.000 - 1.300.000
Senior Employee Relations Investigator
Senior Employee Relations Investigator

Flint Hills Resources • Región Centro

Híbrido
MXN 600.000 - 1.200.000
Hybrid work environment
Senior Employee Relations Investigator
Senior Employee Relations Investigator

Koch • Región Centro

Presencial
MXN 600.000 - 900.000
Business Systems Analyst, HR Applications
Business Systems Analyst, HR Applications

Flint Hills Resources • Región Centro

Presencial
MXN 600.000 - 900.000
Business Systems Analyst, HR Applications
Business Systems Analyst, HR Applications

Koch • Región Centro

Presencial
MXN 480.000 - 720.000
IBM FileNet Developer & Administrator
IBM FileNet Developer & Administrator

Flint Hills Resources • Región Centro

Presencial
MXN 420.000 - 660.000
Quality Control Engineer (NPI)
Quality Control Engineer (NPI)

Molex • Heroica Nogales

Presencial
MXN 400.000 - 700.000
Recruitment Analyst
Recruitment Analyst

Flint Hills Resources • El Salto

Presencial
MXN 300.000 - 540.000